Aesto Health just disclosed a breach that hit 9.5 million patients - and it happened nine months ago.
The Alabama-based healthcare tech vendor, which helps other providers manage electronic health records and switch EHR systems, says unidentified attackers breached parts of its AWS infrastructure between December 2 and December 18, 2025. It only reported the incident to the HHS Office for Civil Rights this week, more than half a year after the fact. Stolen data spans more than 20 client organizations, including Village Practice Management, Everside Health, and Together Women's Health Medical Group, and includes names, Social Security numbers, partial dates of birth, driver's license numbers, financial account numbers, health records, and insurance details. Aesto Health says it has no evidence the data has surfaced on the dark web, and it is offering credit monitoring and identity theft protection to everyone affected.
This is now the second-largest healthcare breach of 2026, behind only the 15-million-record hit on DentaQuest, and it points to a structural problem. Health-tech middlemen that plug into dozens of provider systems become single points of failure - when one gets hit, the damage multiplies across every clinic that outsourced its records to it. A nine-month gap between breach and disclosure also means potentially exposed patients spent most of a year not knowing their SSNs and medical histories were sitting with an unknown attacker.
Credit monitoring is the standard consolation prize here - it does nothing about the fact that stolen Social Security numbers stay stolen for good.